CVE-2019-8696: Buffer Overflow
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, Security Update 2019-004 Sierra. An attacker in a privileged network position may be able to execute arbitrary code.
Other sources
Apple CUPS is vulnerable to a stack-based buffer overflow, caused by improper bounds checking by the libcups's asn1getpacked function. By sending an overly long argument, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.
— IBM
CUPS. A buffer overflow issue was addressed with improved memory handling.
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2019-8693
- CVE-2019-8656
- CVE-2018-19860
- CVE-2019-9506
- CVE-2020-10135
- CVE-2019-8661
- CVE-2019-8646
- CVE-2019-8660
- CVE-2019-8675
- CVE-2019-8696
- CVE-2019-8539
- CVE-2019-8697
- CVE-2019-8648
- CVE-2019-8663
- CVE-2019-8702
- CVE-2019-8695
- CVE-2019-8691
- CVE-2019-8692
- CVE-2018-16860
- CVE-2019-8694
- CVE-2019-13118
- CVE-2019-8662
- CVE-2019-8670
- CVE-2019-8701
- CVE-2019-8667
- CVE-2019-8657
- CVE-2019-8690
- CVE-2019-8649
- CVE-2019-8658
- CVE-2019-8644
- CVE-2019-8666
- CVE-2019-8669
- CVE-2019-8671
- CVE-2019-8672
- CVE-2019-8673
- CVE-2019-8676
- CVE-2019-8677
- CVE-2019-8678
- CVE-2019-8679
- CVE-2019-8680
- CVE-2019-8681
- CVE-2019-8683
- CVE-2019-8684
- CVE-2019-8685
- CVE-2019-8686
- CVE-2019-8687
- CVE-2019-8688
- CVE-2019-8689
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-8696.
What is the severity of CVE-2019-8696?
The severity of CVE-2019-8696 is high with a severity score of 8.8.
What is the affected software?
The affected software includes Apple Mac OS X, Apple macOS Mojave, Apple High Sierra, and Apple Sierra.
How can an attacker exploit CVE-2019-8696?
An attacker in a privileged network position may be able to execute arbitrary code.
How can I fix CVE-2019-8696?
CVE-2019-8696 is fixed in macOS Mojave 10.14.6, Security Update 2019-004 High Sierra, and Security Update 2019-004 Sierra.